Privacy Policy

Heckle — alarms from friends

Last updated: 20 August 2026

Heckle is an alarm app where friends can set alarms for each other. This policy explains exactly what the app collects, why, who it goes to, and how to get rid of it. It is written to match what the app actually does rather than to cover every possibility.

Heckle is operated by Khalid Mansoor. Contact: khalidmansoorr@gmail.com.

What we collect

DataWhy
Email address To create and sign in to your account. Not used for marketing.
Password Stored only as a bcrypt hash. We cannot read it.
Display name and profile photo Shown to your friends so they know who set an alarm.
Alarms Times, labels, repeat settings, timezone and chosen challenges, so the alarm can ring on the right device at the right moment.
Voice recordings Voice messages attached to alarms, and voice comments. Recorded only when you tap the microphone.
Photos Your profile photo, and wake-up selfies if you use the camera challenge. The camera is opened only for those actions.
Comments Text and voice comments you leave on activity posts.
Friends and groups Who you are connected to, so alarms and activity reach the right people.
Wake-up activity Whether you completed or missed an alarm, streaks and badges. This is what the activity feed and leaderboards are built from.
Push notification token A device identifier from Firebase, so alarms and alerts can be delivered.
Purchase status Whether you have an active subscription. We never see your card details.

What we do not collect

Device permissions

What other people can see

Heckle has no public profiles and no global feed. Your name, photo, wake-up activity, streaks and comments are visible only to people you have accepted as friends and to members of groups you have joined.

If you block someone, you and they stop seeing each other's posts and comments entirely, your friendship ends, and neither of you can send the other a request.

Who we share data with

We do not sell your data and we do not share it for advertising. Heckle uses a small number of service providers to run the app. They process data on our instructions only:

ProviderWhat it handles
MongoDB AtlasThe database — accounts, alarms, comments, friendships
VercelHosting for the API
CloudinaryStorage for profile photos, selfies and voice recordings
Google Firebase (FCM)Delivering push notifications
UpstashRate limiting and short-lived caching
RevenueCat and Google PlaySubscriptions and purchase verification

We may also disclose data if the law requires it, or to investigate abuse reported through the app.

How long we keep it

Deleting your account

You can delete your account and its data from inside the app: Profile → Delete my account. It is immediate and cannot be undone.

If you no longer have the app installed, see the account deletion page for how to request it by email.

Your rights

Depending on where you live, you may have the right to access, correct, export or delete your personal data, to object to how it is used, and to complain to your local data protection authority. Email khalidmansoorr@gmail.com and we will respond within 30 days.

Children

Heckle is not directed at children under 13, and we do not knowingly collect data from them. If you believe a child has created an account, email us and we will delete it.

Security

All traffic between the app and our servers uses HTTPS. Passwords are stored as bcrypt hashes and are never readable by us or by anyone with database access. No system is perfectly secure, but we do not keep data we do not need.

Changes to this policy

If this policy changes in a way that affects you, we will update the date at the top and, for significant changes, tell you in the app.